Glossary · Automation fundamentals, platforms and components
Encryption
Also known as: Data encryption
German: Verschlüsselung
In information security, encryption is the transformation of data into a form that can only be read with the matching key, protecting its confidentiality in transit or at rest.
- Automation components
- OT security
In one sentence
Encryption transforms data so only holders of the matching key can read it, protecting confidentiality in transit or at rest.
Example
The OPC UA connection between SCADA and the PLC uses the SignAndEncrypt security mode, so recipe data cannot be read on the network.
How it applies
- Engineering: Industrial protocols add encryption through TLS or protocol-specific security, for example OPC UA security modes. Older fieldbuses and many real-time protocols do not encrypt.
- Operation: Keys and certificates must be managed: generated, distributed, renewed and revoked. Expired certificates are a common cause of connection failures.
- Documentation: Security manuals should state which interfaces encrypt, which algorithms and protocol versions are supported, and how certificates are handled. Describe the limits too, such as unencrypted service ports.
Encryption vs. integrity protection
Encryption protects confidentiality. It does not by itself prove who sent the data or that it was not changed; that requires Authentication and integrity mechanisms such as message authentication codes or signatures. In OT, integrity and availability are often more critical than confidentiality.